Ongoing operations
Automated access reviews
ISO 27001 Annex A controls A.5.15 through A.5.18 cover access control, identity management and the review of access rights. The identity audit scan engine checks a connected identity provider directly for the two failures that actually cause access-control incidents: accounts without multi-factor authentication, and dormant or former-employee accounts nobody remembered to revoke.
Transcript
Access reviews are not a box-ticking exercise under ISO 27001. Annex A controls A.5.15 through A.5.18 require you to actually confirm access rights match business need, not just assert that they do.
A scan result dated today is worth more than a policy document written two years ago. The identity audit engine checks a connected identity provider directly, for accounts without multi-factor authentication, and for dormant or former-employee accounts that were never revoked.
Setting one up is the same as any other connector: a name, the identity provider, and its credentials. Google Workspace, GitHub organisations and Microsoft 365 are all real, working connector types today.
Each finding attaches directly to the connector, dated and severity-rated, so "we reviewed access" becomes "here is exactly what we found, and when".
That evidence feeds a real obligation. ISO 27001 A.5.15 flips to completed automatically once a current review confirms multi-factor authentication is enforced and no dormant accounts remain. No manual checkbox, no separate report to write.
Why this is required
A.5.18 requires access rights to be provisioned, reviewed, modified and removed according to policy. "Reviewed" is the word that is hardest to evidence honestly: a policy document describing a review process is not the same as proof the review happened, on a specific date, against real accounts.
Former-employee and dormant accounts are also one of the most common real-world entry points for account takeover, which is why A.5.16 and A.5.17 exist alongside A.5.18 rather than access rights being covered by a single control.
What EuroCompliant does
A scan connector points the identity audit engine at a real identity provider: Google Workspace, a GitHub organisation, or Microsoft 365. Each connector type has its own real credential fields, following the same connector model automated scanning already uses for infrastructure sources.
Findings are dated and severity-rated: an account without multi-factor authentication enforced, or an account with no sign-in activity past a threshold, each attach to the connector as a specific, timestamped result rather than a general assertion.
That evidence feeds a real obligation automatically. ISO 27001 A.5.15 flips to completed once a current review confirms multi-factor authentication is enforced and no dormant accounts remain, and flips back if a new finding appears, so the obligation status always reflects what was actually found, not what was found once.
Walking through it
Connect an identity provider
Google Workspace, a GitHub organisation, or Microsoft 365, each with its own real credential fields.
Open /settings/scan-connectors →Run or schedule the identity audit scan
On demand for a one-off review, or on a recurring schedule so the evidence stays current rather than aging.
Open /scans →Review findings by severity
Missing multi-factor authentication and dormant accounts are dated findings attached directly to the connector.
Open /scans →The law
Frequently asked
Does this replace a manual access review entirely?
It replaces the evidence-gathering part. A person still decides whether a flagged account's access is actually still needed; the scan tells you which accounts need that decision made, and when it was last checked.
What happens if I don't have a real identity provider connected yet?
The ISO 27001 A.5.15 obligation stays in its not-started state until a connector exists. It does not fail or block anything else in the platform.
Related guides
Integrations, scanning and vendor risk
Connecting your infrastructure for automated scanning, wiring up notifications, and tracking third-party risk.
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial